PDM: warn
B-2-4 overlap, parent first
static (inside,outside) tcp 1.1.1.0 80 1.1.1.0 80 netmask 255.255.255.0
static (inside,outside) tcp 1.1.1.1 80 1.1.1.1 8080 netmask 255.255.255.255
PIX: accept
PDM: warn
B-3 overlap with interface IP
ip address outside 192.168.1.1 255.255.255.0
static (inside,outside) tcp 192.168.1.0 80 1.1.1.0 8080 netmask 255.255.255.0
PIX: accept
PDM: accept
B-4 overlap with global pool
global (outside) 1 192.168.1.1-192.168.1.10
static (inside,outside) tcp 192.168.1.2 80 1.1.1.2 8080 netmask 255.255.255.255
PIX: accept
PDM: accept
C. Static PAT and NAT
Combinations of all cases mentioned in A and B. Overlapping between static NAT
and PAT is bad. It creates unpredictable address translation on PIX. Listed are some possible
misconfigurations you may encounter.
C-1 static and PAT for single address
C-1-1 static first
static (inside,outside) 1.1.1.1 1.1.1.1 netmask 255.255.255.255
static (inside,outside) tcp 1.1.1.1 80 1.1.1.1 8080 netmask 255.255.255.255
PIX: reject
PDM: reject
C-1-2 PAT first
static (inside,outside) tcp 1.1.1.1 80 1.1.1.1 8080 netmask 255.255.255.255
static (inside,outside) 1.1.1.1 1.1.1.1 netmask 255.255.255.255
PIX: accept
PDM: reject
C-2 general static, with exception of PAT for a single address
C-2-1 static first
static (inside,outside) 1.1.1.0 1.1.1.0 netmask 255.255.255.0
static (inside,outside) tcp 1.1.1.1 80 1.1.1.1 8080 netmask 255.255.255.255
PIX: warn
Summary of Contents for PIX 520 - PIX Firewall 520
Page 45: ...Copyright 2001 Cisco Systems Inc ...
Page 68: ...Copyright 2001 Cisco Systems Inc ...
Page 74: ...Copyright 2001 Cisco Systems Inc ...
Page 87: ...Copyright 2001 Cisco Systems Inc ...
Page 92: ...Copyright 2001 Cisco Systems Inc ...
Page 108: ......
Page 184: ......
Page 197: ...Copyright 2001 Cisco Systems Inc ...
Page 200: ......
Page 232: ...Copyright 2001 Cisco Systems Inc ...
Page 246: ...Copyright 2001 Cisco Systems Inc ...